-
Notifications
You must be signed in to change notification settings - Fork 2.8k
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Allow to inject ResourceInfo into custom HTTP Security Policy
- Loading branch information
1 parent
4b8a27a
commit 0f0df56
Showing
9 changed files
with
270 additions
and
23 deletions.
There are no files selected for viewing
38 changes: 38 additions & 0 deletions
38
.../deployment/src/test/java/io/quarkus/resteasy/test/security/CustomHttpSecurityPolicy.java
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,38 @@ | ||
package io.quarkus.resteasy.test.security; | ||
|
||
import jakarta.enterprise.context.ApplicationScoped; | ||
import jakarta.inject.Inject; | ||
import jakarta.ws.rs.container.ResourceInfo; | ||
|
||
import io.quarkus.security.identity.SecurityIdentity; | ||
import io.quarkus.security.runtime.QuarkusSecurityIdentity; | ||
import io.quarkus.vertx.http.runtime.security.HttpSecurityPolicy; | ||
import io.smallrye.mutiny.Uni; | ||
import io.vertx.ext.web.RoutingContext; | ||
|
||
@ApplicationScoped | ||
public class CustomHttpSecurityPolicy implements HttpSecurityPolicy { | ||
|
||
@Inject | ||
ResourceInfo resourceInfo; | ||
|
||
@Override | ||
public Uni<CheckResult> checkPermission(RoutingContext request, Uni<SecurityIdentity> identity, | ||
AuthorizationRequestContext requestContext) { | ||
if ("CustomPolicyResource".equals(resourceInfo.getResourceClass().getSimpleName()) | ||
&& "isUserAdmin".equals(resourceInfo.getResourceMethod().getName())) { | ||
return identity.onItem().ifNotNull().transform(i -> { | ||
if (i.hasRole("user")) { | ||
return new CheckResult(true, QuarkusSecurityIdentity.builder(i).addRole("admin").build()); | ||
} | ||
return CheckResult.PERMIT; | ||
}); | ||
} | ||
return Uni.createFrom().item(CheckResult.PERMIT); | ||
} | ||
|
||
@Override | ||
public String name() { | ||
return "custom"; | ||
} | ||
} |
55 changes: 55 additions & 0 deletions
55
...ava/io/quarkus/resteasy/test/security/CustomHttpSecurityWithJaxRsSecurityContextTest.java
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,55 @@ | ||
package io.quarkus.resteasy.test.security; | ||
|
||
import org.hamcrest.Matchers; | ||
import org.jboss.shrinkwrap.api.asset.StringAsset; | ||
import org.junit.jupiter.api.BeforeAll; | ||
import org.junit.jupiter.api.Test; | ||
import org.junit.jupiter.api.extension.RegisterExtension; | ||
|
||
import io.quarkus.security.test.utils.TestIdentityController; | ||
import io.quarkus.security.test.utils.TestIdentityProvider; | ||
import io.quarkus.test.QuarkusUnitTest; | ||
import io.restassured.RestAssured; | ||
|
||
public class CustomHttpSecurityWithJaxRsSecurityContextTest { | ||
|
||
@RegisterExtension | ||
static QuarkusUnitTest runner = new QuarkusUnitTest() | ||
.withApplicationRoot((jar) -> jar | ||
.addClasses(CustomPolicyResource.class, TestIdentityProvider.class, | ||
TestIdentityController.class, CustomHttpSecurityPolicy.class) | ||
.addAsResource(new StringAsset(""" | ||
quarkus.http.auth.permission.custom-policy-1.paths=/custom-policy/is-admin | ||
quarkus.http.auth.permission.custom-policy-1.policy=custom | ||
quarkus.http.auth.permission.custom-policy-1.applies-to=JAXRS | ||
"""), | ||
"application.properties")); | ||
|
||
@BeforeAll | ||
public static void setupUsers() { | ||
TestIdentityController.resetRoles() | ||
.add("test", "test", "test") | ||
.add("user", "user", "user"); | ||
} | ||
|
||
@Test | ||
public void testAugmentedIdentityInSecurityContext() { | ||
// test that custom HTTP Security Policy is applied, it added 'admin' role to the 'user' | ||
// and this new role is present in the JAX-RS SecurityContext | ||
RestAssured | ||
.given() | ||
.auth().preemptive().basic("user", "user") | ||
.get("/custom-policy/is-admin") | ||
.then() | ||
.statusCode(200) | ||
.body(Matchers.is("true")); | ||
RestAssured | ||
.given() | ||
.auth().preemptive().basic("test", "test") | ||
.get("/custom-policy/is-admin") | ||
.then() | ||
.statusCode(200) | ||
.body(Matchers.is("false")); | ||
} | ||
|
||
} |
17 changes: 17 additions & 0 deletions
17
...easy/deployment/src/test/java/io/quarkus/resteasy/test/security/CustomPolicyResource.java
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,17 @@ | ||
package io.quarkus.resteasy.test.security; | ||
|
||
import jakarta.ws.rs.GET; | ||
import jakarta.ws.rs.Path; | ||
import jakarta.ws.rs.core.Context; | ||
import jakarta.ws.rs.core.SecurityContext; | ||
|
||
@Path("custom-policy") | ||
public class CustomPolicyResource { | ||
|
||
@Path("is-admin") | ||
@GET | ||
public boolean isUserAdmin(@Context SecurityContext context) { | ||
return context.isUserInRole("admin"); | ||
} | ||
|
||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
38 changes: 38 additions & 0 deletions
38
...test/java/io/quarkus/resteasy/reactive/server/test/security/CustomHttpSecurityPolicy.java
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,38 @@ | ||
package io.quarkus.resteasy.reactive.server.test.security; | ||
|
||
import jakarta.enterprise.context.ApplicationScoped; | ||
import jakarta.inject.Inject; | ||
import jakarta.ws.rs.container.ResourceInfo; | ||
|
||
import io.quarkus.security.identity.SecurityIdentity; | ||
import io.quarkus.security.runtime.QuarkusSecurityIdentity; | ||
import io.quarkus.vertx.http.runtime.security.HttpSecurityPolicy; | ||
import io.smallrye.mutiny.Uni; | ||
import io.vertx.ext.web.RoutingContext; | ||
|
||
@ApplicationScoped | ||
public class CustomHttpSecurityPolicy implements HttpSecurityPolicy { | ||
|
||
@Inject | ||
ResourceInfo resourceInfo; | ||
|
||
@Override | ||
public Uni<CheckResult> checkPermission(RoutingContext request, Uni<SecurityIdentity> identity, | ||
AuthorizationRequestContext requestContext) { | ||
if ("CustomPolicyResource".equals(resourceInfo.getResourceClass().getSimpleName()) | ||
&& "isUserAdmin".equals(resourceInfo.getResourceMethod().getName())) { | ||
return identity.onItem().ifNotNull().transform(i -> { | ||
if (i.hasRole("user")) { | ||
return new CheckResult(true, QuarkusSecurityIdentity.builder(i).addRole("admin").build()); | ||
} | ||
return CheckResult.PERMIT; | ||
}); | ||
} | ||
return Uni.createFrom().item(CheckResult.PERMIT); | ||
} | ||
|
||
@Override | ||
public String name() { | ||
return "custom"; | ||
} | ||
} |
55 changes: 55 additions & 0 deletions
55
...esteasy/reactive/server/test/security/CustomHttpSecurityWithJaxRsSecurityContextTest.java
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,55 @@ | ||
package io.quarkus.resteasy.reactive.server.test.security; | ||
|
||
import org.hamcrest.Matchers; | ||
import org.jboss.shrinkwrap.api.asset.StringAsset; | ||
import org.junit.jupiter.api.BeforeAll; | ||
import org.junit.jupiter.api.Test; | ||
import org.junit.jupiter.api.extension.RegisterExtension; | ||
|
||
import io.quarkus.security.test.utils.TestIdentityController; | ||
import io.quarkus.security.test.utils.TestIdentityProvider; | ||
import io.quarkus.test.QuarkusUnitTest; | ||
import io.restassured.RestAssured; | ||
|
||
public class CustomHttpSecurityWithJaxRsSecurityContextTest { | ||
|
||
@RegisterExtension | ||
static QuarkusUnitTest runner = new QuarkusUnitTest() | ||
.withApplicationRoot((jar) -> jar | ||
.addClasses(CustomPolicyResource.class, TestIdentityProvider.class, | ||
TestIdentityController.class, CustomHttpSecurityPolicy.class) | ||
.addAsResource(new StringAsset(""" | ||
quarkus.http.auth.permission.custom-policy-1.paths=/custom-policy/is-admin | ||
quarkus.http.auth.permission.custom-policy-1.policy=custom | ||
quarkus.http.auth.permission.custom-policy-1.applies-to=JAXRS | ||
"""), | ||
"application.properties")); | ||
|
||
@BeforeAll | ||
public static void setupUsers() { | ||
TestIdentityController.resetRoles() | ||
.add("test", "test", "test") | ||
.add("user", "user", "user"); | ||
} | ||
|
||
@Test | ||
public void testAugmentedIdentityInSecurityContext() { | ||
// test that custom HTTP Security Policy is applied, it added 'admin' role to the 'user' | ||
// and this new role is present in the JAX-RS SecurityContext | ||
RestAssured | ||
.given() | ||
.auth().preemptive().basic("user", "user") | ||
.get("/custom-policy/is-admin") | ||
.then() | ||
.statusCode(200) | ||
.body(Matchers.is("true")); | ||
RestAssured | ||
.given() | ||
.auth().preemptive().basic("test", "test") | ||
.get("/custom-policy/is-admin") | ||
.then() | ||
.statusCode(200) | ||
.body(Matchers.is("false")); | ||
} | ||
|
||
} |
16 changes: 16 additions & 0 deletions
16
...src/test/java/io/quarkus/resteasy/reactive/server/test/security/CustomPolicyResource.java
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,16 @@ | ||
package io.quarkus.resteasy.reactive.server.test.security; | ||
|
||
import jakarta.ws.rs.GET; | ||
import jakarta.ws.rs.Path; | ||
import jakarta.ws.rs.core.SecurityContext; | ||
|
||
@Path("custom-policy") | ||
public class CustomPolicyResource { | ||
|
||
@Path("is-admin") | ||
@GET | ||
public boolean isUserAdmin(SecurityContext context) { | ||
return context.isUserInRole("admin"); | ||
} | ||
|
||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters